SecureW2 connects to Entra ID for SAML-based certificate enrollment across managed and unmanaged devices; no MDM agent is required for BYOD. At every 802.1X authentication event, Cloud RADIUS performs a live Entra ID lookup to verify account status, group membership, and Entra ID Protection risk score, so network access always reflects the user’s current identity state.
Overview
SecureW2 integrates with Microsoft Entra ID for passwordless, certificate-based authentication for Wi-Fi, VPN, and applications. It uses Entra ID as the SAML 2.0 identity provider for JoinNow self-service certificate enrollment. Users authenticate through Entra ID SSO, and SecureW2 issues a device-bound certificate with Entra ID attributes like group membership and department. These certificates enable EAP-TLS 802.1X authentication across MDM-managed and unmanaged devices without passwords.
JoinNow Cloud RADIUS performs real-time lookups against Entra ID during RADIUS authentication events to verify user status, group membership, and Entra ID Risk Protection score. Changes in Entra ID signals deprovision users, move them to different groups, or flag them as risky. SecureW2 adjusts network access and VLAN assignment at the next authentication. Dynamic webhooks allow Entra ID to push signal changes to SecureW2 out-of-band.
Entra ID serves as the SAML 2.0 identity provider. The JoinNow onboarding client redirects users to Entra ID SSO, receives a SAML assertion containing user attributes, and uses those attributes to issue a device-bound certificate. The device authenticates to Wi-Fi using EAP-TLS, with no password required.
At every 802.1X authentication event, Cloud RADIUS queries Entra ID via OAuth 2.0 to verify the user’s current status, group membership, and Risk Protection score. VLAN assignment is driven by live Entra ID data, not a cached snapshot. Dynamic webhooks allow Entra ID to push signal changes between sessions.
SecureW2-issued certificates serve as device identity proof beyond the network layer, enabling Conditional Access to gate access to M365, Azure AD-connected applications, and Entra ID-protected resources. When a user attempts to access a protected application, Entra ID Conditional Access checks for a trusted certificate issued by the SecureW2 CA. Devices without a valid certificate are blocked at the application layer, regardless of network location.
This extends the value of a single certificate enrollment across multiple access surfaces. The same certificate authenticates a device to Wi-Fi via EAP-TLS and satisfies device compliance for application access, eliminating the need for separate credentials or enrollment steps. When a user is offboarded and their certificate is revoked via webhook, that revocation simultaneously removes network access through Cloud RADIUS and application access through Conditional Access, closing both surfaces from a single directory event in Entra ID.
When a user account is disabled, removed from a group, or flagged as high-risk in Entra ID, a dynamic webhook sends an out-of-band signal to SecureW2, revoking the user’s certificate and making the credential invalid. Cloud RADIUS denies the device’s connection request due to the revoked certificate and the real-time Entra ID lookup confirming the account’s inactivity.
This two-layer enforcement ensures immediate reflection of offboarding and risk escalation on the network, not at the next scheduled sync or certificate expiry. Administrators can configure revocation triggers to match specific Entra ID events, such as account disabled, group removal, MFA failure threshold exceeded, or a Risk Protection score crossing a defined threshold. Revocation applies across all network access points enforced by Cloud RADIUS, Wi-Fi, wired 802.1X, and VPN.
Frequently Asked Questions
JoinNow uses Entra ID as a SAML 2.0 identity provider. When a user runs the JoinNow onboarding client, the client redirects to Entra ID for credential verification. After authentication, Entra ID returns a SAML assertion with the user's attributes, which SecureW2 uses to populate and issue a device-bound certificate.
Real-time lookups. At each 802.1X authentication event, Cloud RADIUS queries Entra ID via OAuth 2.0 to verify the user's current status, group membership, and Risk Protections score. Dynamic webhooks also allow Entra ID to push signal changes to SecureW2 between authentication events.
Administrators map Entra ID groups and roles to VLANs in the Cloud RADIUS policy. When a user authenticates, Cloud RADIUS confirms their current Entra ID group membership and assigns the corresponding VLAN. If group membership changes, the next authentication reflects the updated assignment automatically.
Cloud RADIUS will deny the user's next authentication request based on the real-time identity lookup. SecureW2 can also revoke the user's certificate immediately, so the credential itself becomes invalid. Both the RADIUS lookup and certificate revocation work together to remove access promptly.
Yes. JoinNow self-service onboarding is designed for both managed and unmanaged devices. Users authenticate through Entra ID SSO and receive a certificate through the same enrollment flow regardless of whether their device is enrolled in an MDM. EAP-TLS authentication works across Windows, macOS, iOS, Android, and ChromeOS.
SAML 2.0 for enrollment identity verification, OAuth 2.0 and OpenID Connect for real-time Entra ID lookups from Cloud RADIUS, LDAP, 802.1X EAP-TLS for network authentication, WPA2/WPA3 Enterprise, and webhooks for dynamic API triggers from Entra ID.
SecureW2 cites the guided setup wizard as completable in 10–15 minutes for the Entra ID connection, with full cert-based Wi-Fi deployment achievable in approximately 30 minutes.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.